🔥 40% Off Crucial Exams Memberships — Deal ends today!

1 hour, 26 minutes remaining!

GCP Professional Cloud Security Engineer Practice Question

Your organization grants the Google Group "[email protected]" the Viewer role (roles/viewer) at the Organization node so that internal audit staff can list and read resources in every project. A new project called "mna-risk-analysis" will contain highly confidential data that auditors must not access. The project must stay within the existing organization hierarchy, and you must follow the principle of least privilege while avoiding disruptive changes to other projects. How should you prevent the auditors from viewing resources in the new project?

  • Add a conditional role binding at the project level that grants [email protected] the Viewer role only when resource.type != "project".

  • Delete the existing Viewer binding at the Organization level and re-create identical Viewer bindings on every other folder and project except mna-risk-analysis.

  • Move the mna-risk-analysis project into a new Google Cloud organization that has no Viewer role for [email protected].

  • Attach an IAM Deny policy to the mna-risk-analysis project that blocks the [email protected] group from the viewer permissions they inherit.

GCP Professional Cloud Security Engineer
Configuring Access
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot